Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

New Remote Code Execution Risk in Common Windows and Linux Tools

A new security weakness has been reported that could allow attackers to run harmful software on your computers by exploiting how some Windows and Linux systems handle certain network communications. This matters because it could let criminals take control of your devices remotely if not addressed.

18 July 2026

1. What is being reported?

Security researchers have found a way to use a network relay technique involving HTTP and SMB protocols to execute malicious code remotely on affected systems. This involves tricking a computer into accepting harmful instructions over the network, potentially leading to full control by an attacker.

2. What this means in plain English

If your organisation uses Windows or Linux systems that handle remote desktop or file sharing services, there is a risk that attackers could exploit this weakness to access your data or disrupt your operations without your permission.

3. Could this affect a small business?

Small businesses using common Windows or Linux software, including remote desktop or file sharing features, could be affected. Those who do not use these services or keep their systems updated are less likely to be at risk.

4. What to do now

  • Check with your IT provider whether your systems are affected by this vulnerability.
  • Ensure all Windows and Linux systems are fully updated with the latest security patches.
  • Limit exposure of remote desktop and file sharing services to the internet where possible.
  • Monitor your systems for unusual activity and report any concerns promptly.

5. Ask your IT provider

Can you confirm if our Windows and Linux systems are protected against the recent remote code execution vulnerability involving HTTP to SMB relay attacks?

6. Bottom line

Keep your systems updated and limit exposure to reduce the risk of attackers taking control remotely.

Information based on reputable security reporting and CISA KEV.

Back to Vulnerability Briefs